@@ -12,6 +12,7 @@ import {
1212 createExecToolCallGate ,
1313 createExecToolPromoter ,
1414 execUserFailureMessage ,
15+ formatExecMcpTrustQuestion ,
1516 refreshSelectedProviderCredential ,
1617 resolveExecDirectorOverlay ,
1718 runExec ,
@@ -70,6 +71,58 @@ function bareConfig(task: string): Config {
7071 } as unknown as Config ;
7172}
7273
74+ describe ( "exec MCP trust prompt" , ( ) => {
75+ test ( "shows a stdio command with literal space-joined args" , ( ) => {
76+ const question = formatExecMcpTrustQuestion ( {
77+ name : "filesystem" ,
78+ command : "npx" ,
79+ args : [ "-y" , "@modelcontextprotocol/server-filesystem" , "/tmp/work" ] ,
80+ } ) ;
81+
82+ expect ( question ) . toBe (
83+ 'Trust local MCP server "filesystem" for this project?\nCommand: npx -y @modelcontextprotocol/server-filesystem /tmp/work' ,
84+ ) ;
85+ } ) ;
86+
87+ test ( "shows only the stdio command when args are omitted" , ( ) => {
88+ expect ( formatExecMcpTrustQuestion ( { name : "local" , command : "node" } ) ) . toBe (
89+ 'Trust local MCP server "local" for this project?\nCommand: node' ,
90+ ) ;
91+ } ) ;
92+
93+ test ( "shows only the stdio command when args are empty" , ( ) => {
94+ expect (
95+ formatExecMcpTrustQuestion ( { name : "local" , command : "node" , args : [ ] } ) ,
96+ ) . toBe ( 'Trust local MCP server "local" for this project?\nCommand: node' ) ;
97+ } ) ;
98+
99+ test ( "shows an HTTP server URL" , ( ) => {
100+ expect (
101+ formatExecMcpTrustQuestion ( {
102+ name : "remote" ,
103+ type : "http" ,
104+ url : "https://mcp.example.test/api" ,
105+ } ) ,
106+ ) . toBe (
107+ 'Trust local MCP server "remote" for this project?\nURL: https://mcp.example.test/api' ,
108+ ) ;
109+ } ) ;
110+
111+ test ( "does not show environment secrets" , ( ) => {
112+ const question = formatExecMcpTrustQuestion ( {
113+ name : "private" ,
114+ command : "private-server" ,
115+ env : { API_TOKEN : "super-secret" } ,
116+ } ) ;
117+
118+ expect ( question ) . toBe (
119+ 'Trust local MCP server "private" for this project?\nCommand: private-server' ,
120+ ) ;
121+ expect ( question ) . not . toContain ( "API_TOKEN" ) ;
122+ expect ( question ) . not . toContain ( "super-secret" ) ;
123+ } ) ;
124+ } ) ;
125+
73126describe ( "formatCaughtError" , ( ) => {
74127 test ( "prefers Error.message and stringifies other values" , ( ) => {
75128 expect ( formatCaughtError ( new Error ( "disk full" ) ) ) . toBe ( "disk full" ) ;
0 commit comments